Latest Cybersecurity News and Articles


Researchers Uncover Major Security Vulnerabilities in Industrial MMS Protocol Libraries

09 October 2024
Details have emerged about multiple security vulnerabilities in two implementations of the Manufacturing Message Specification (MMS) protocol that, if successfully exploited, could have severe impacts in industrial environments. "The vulnerabilities could allow an attacker to crash an industrial device or in some cases, enable remote code execution," Claroty researchers Mashav Sapir and Vera

Rejoice! The charade of having to change our passwords every few months is coming to an end | Kate O'Flaherty

09 October 2024
Rejoice! The charade of having to change our passwords every few months is coming to an end | Kate O'Flaherty The US government is finally admitting there’s no need – instead, to fend off cyber-attacks we need passwords that are long but memorableOver the past decade or so, people have accumulated a vast array of logins for dozens of sites and apps, as more of our work and home lives moves on to the internet. That’s why it has never made sense that so many IT departments have belligerently insisted on maintaining a major hurdle to password management. Namely, the need to change passwords regularly.It’s a familiar scenario. You arrive at the office and need to log on to your company laptop quickly, before your morning meeting. But speed is not going to be of the essence today, because an annoying prompt has appeared: you need to change your password.Kate O’Flaherty is a freelance technology journalist Continue reading...

N. Korean Hackers Use Fake Interviews to Infect Developers with Cross-Platform Malware

09 October 2024
Threat actors with ties to North Korea have been observed targeting job seekers in the tech industry to deliver updated versions of known malware families tracked as BeaverTail and InvisibleFerret. The activity cluster, tracked as CL-STA-0240, is part of a campaign dubbed Contagious Interview that Palo Alto Networks Unit 42 first disclosed in November 2023. "The threat actor behind CL-STA-0240

35% of UK security leaders cite competition as cause of skills shortage

09 October 2024
Issues faced by IT leaders in the U.K. were analyzed in a recent Hyve Managed Hosting report, including the current cybersecurity talent gap.

Russian hacking group intercepted by Microsoft and DOJ

09 October 2024
Microsoft and the United States Department of Justice has announced the disruption of COLDRIVER’s technical infrastructure. 

Social Media Accounts: The Weak Link in Organizational SaaS Security

09 October 2024
Social media accounts help shape a brand’s identity and reputation. These public forums engage directly with customers as they are a hub to connect, share content and answer questions. However, despite the high profile role these accounts have, many organizations overlook social media account security. Many lack the safeguards to prevent unauthorized access — a situation no organization wants as

Microsoft Issues Security Update Fixing 118 Flaws, Two Actively Exploited in the Wild

09 October 2024
Microsoft has released security updates to fix a total of 118 vulnerabilities across its software portfolio, two of which have come under active exploitation in the wild. Of the 118 flaws, three are rated Critical, 113 are rated Important, and two are rated Moderate in severity. The Patch Tuesday update doesn't include the 25 additional flaws that the tech giant addressed in its Chromium-based

Microsoft Detects Growing Use of File Hosting Services in Business Email Compromise Attacks

09 October 2024
Microsoft is warning of cyber attack campaigns that abuse legitimate file hosting services such as SharePoint, OneDrive, and Dropbox that are widely used in enterprise environments as a defense evasion tactic. The end goal of the campaigns are broad and varied, allowing threat actors to compromise identities and devices and conduct business email compromise (BEC) attacks, which ultimately result

Finance industry most at risk for phishing attacks

09 October 2024
Phishing attacks targeted the finance industry in H1 2024.

47% of Organizations Have Dealt With Deepfake Attacks

09 October 2024
Deepfake attacks are on the rise.

Patch Tuesday, October 2024 Edition

08 October 2024
Microsoft today released security updates to fix at least 117 security holes in Windows computers and other software, including two vulnerabilities that are already seeing active attacks. Also, Adobe plugged 52 security holes across a range of products, and Apple has addressed a bug in its new macOS 15 "Sequoia" update that broke many cybersecurity tools.

Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited

08 October 2024
Ivanti has warned that three new security vulnerabilities impacting its Cloud Service Appliance (CSA) have come under active exploitation in the wild. The zero-day flaws are being weaponized in conjunction with another flaw in CSA that the company patched last month, the Utah-based software services provider said. Successful exploitation of these vulnerabilities could allow an authenticated

Gamers Tricked Into Downloading Lua-Based Malware via Fake Cheating Script Engines

08 October 2024
Users searching for game cheats are being tricked into downloading a Lua-based malware that is capable of establishing persistence on infected systems and delivering additional payloads. "These attacks capitalize on the popularity of Lua gaming engine supplements within the student gamer community," Morphisec researcher Shmuel Uzan said in a new report published today, adding "this malware

81% of U.S. workers have not been trained on generative AI

08 October 2024
Security practices were analyzed in a recent report, finding that one in two office workers admit to using personal devices to log into work networks.

Security leaders discuss the new vulnerability added to CISA’s catalog

08 October 2024
CISA has issued a warning regarding a known, exploited vulnerability.

Team of British women to take part in international cyber event in Japan

08 October 2024
A team of CyberFirst Bursary alumni will join teams from Japan, the USA, and Europe at the inaugural Kunoichi Cyber Games in November.

Cyberattack Group 'Awaken Likho' Targets Russian Government with Advanced Tools

08 October 2024
Russian government agencies and industrial entities are the target of an ongoing activity cluster dubbed Awaken Likho. "The attackers now prefer using the agent for the legitimate MeshCentral platform instead of the UltraVNC module, which they had previously used to gain remote access to systems," Kaspersky said, detailing a new campaign that began in June 2024 and continued at least until

New Case Study: The Evil Twin Checkout Page

08 October 2024
Is your store at risk? Discover how an innovative web security solution saved one global online retailer and its unsuspecting customers from an “evil twin” disaster. Read the full real-life case study here. The Invisible Threat in Online Shopping When is a checkout page, not a checkout page? When it's an “evil twin”! Malicious redirects can send unsuspecting shoppers to these perfect-looking

The Value of AI-Powered Identity

08 October 2024
Introduction Artificial intelligence (AI) deepfakes and misinformation may cause worry in the world of technology and investment, but this powerful, foundational technology has the potential to benefit organizations of all kinds when harnessed appropriately. In the world of cybersecurity, one of the most important areas of application of AI is augmenting and enhancing identity management

GoldenJackal Target Embassies and Air-Gapped Systems Using Malware Toolsets

08 October 2024
A little-known threat actor tracked as GoldenJackal has been linked to a series of cyber attacks targeting embassies and governmental organizations with an aim to infiltrate air-gapped systems using two disparate bespoke toolsets. Victims included a South Asian embassy in Belarus and a European Union government (E.U.) organization, Slovak cybersecurity company ESET said. "The ultimate goal of